Opening the Black Box: Agentless Threat Detection for Virtual Appliances
ID: 625c9793-d9bf-58a1-8bed-b99b8ef9b7c0
STIX ID: report--625c9793-d9bf-58a1-8bed-b99b8ef9b7c0
Feed Name: Wiz Blog
This report explains that internet-facing virtual appliances—especially FortiGate NGFW instances—are high-value, internet-exposed targets and documents active exploitation (including CVE-2026-24858 and large-scale credential-stuffing/FortiBleed activity). It provides a Wiz agentless detection playbook that maps attacker techniques to FortiGate log IDs, sample log entries, hunt criteria, and recommended detections for persistence, NAT abuse, config exfiltration, lateral movement, and malicious certificate or account changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
